Context.ai OAuth Token Compromise: SaaS Integration-Layer Supply Chain Attack
Context.ai OAuth Token Compromise (TL-2026-0398), also tracked as ContextHarvest Operation, is a critical-severity supply-chain compromise scored CVSS 9.1, first published 2026-04-20. It is attributed to UNC6438 with medium confidence, affects Context.ai Context.ai SaaS data-ingestion platform, maps to 18 MITRE ATT&CK techniques (T1071.001, T1078.004, T1087.004), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0398
- Threat ID
- TL-2026-0398
- Also known as
- ContextHarvest Operation, Context.ai Token Heist, OAuthSpring-2026
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- 2026-04-20
- Last reviewed
- 2026-04-20
- Attribution
- UNC6438
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, financial, healthcare, defense, professional-services, saas
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Context.ai OAuth Token Compromise
Malware and tooling: Custom Go-based OAuth relay (internally named 'cxharvest')
Attackers stole OAuth refresh tokens issued to Context.ai, a SaaS data-ingestion platform, and abused the trust relationships to pivot into downstream customer tenants via connected Salesforce, HubSpot, Slack, and Google Workspace integrations. No Context.ai code was modified; the compromise lives entirely at the integration layer, giving the actor read/write access to every tenant that had granted Context.ai OAuth scopes. Wiz researchers disclosed the incident on 2026-04-20 after observing mass-scale data exfiltration from dozens of victim tenants.
How Context.ai OAuth Token Compromise works
On 2026-04-19, Wiz Threat Research identified anomalous API traffic originating from Context.ai infrastructure ranges against multiple unrelated Salesforce and Google Workspace customer tenants. Investigation determined that on or about 2026-04-08 an unknown actor obtained access to Context.ai's production secrets management system (HashiCorp Vault) via a compromised GitHub Actions workflow that logged a long-lived personal access token to a public build artifact. The actor used the Vault access to enumerate and exfiltrate the OAuth refresh tokens Context.ai had accumulated for every customer-granted integration, approximately 3,400 active refresh tokens covering Salesforce (T1199), HubSpot, Slack, Google Workspace, Microsoft 365, Notion, Zendesk, and GitHub.
For ~11 days the actor used these tokens from a rotating pool of residential proxy IPs (NSOCKS, 911 S5 successor) and datacenter ranges in Hetzner, OVH, and DigitalOcean to issue legitimate-looking API calls against each downstream tenant. Because the tokens were valid and scoped as the tenant had originally authorized (typical scopes: read:all-contacts, read:all-deals, read:drive.readonly, channels:history, files:read), the traffic passed authentication and logged as Context.ai activity in each tenant's audit log — there was no malware, no phishing, and no unusual login from the end-user perspective.
Exfiltration targeted three data classes: (1) CRM records (Salesforce accounts, opportunities, contacts — particularly from Context.ai customers in the defense, fintech, and healthcare verticals), (2) Slack DMs and private channel history for executive and security-team conversations, and (3) Google Drive documents matching regex patterns for API keys, AWS credentials, and SSO SAML signing certificates. Wiz observed at least 14 victim tenants from which secondary compromise followed — attackers used Drive-harvested AWS keys to provision compute in victim AWS accounts, and used harvested SAML signing certificates to forge session tokens for downstream SaaS apps (Golden SAML pattern, T1606.002).
Context.ai rotated all OAuth refresh tokens and revoked customer integrations on 2026-04-19, forcing every customer to re-authorize. CISA issued an alert the same day urging all Context.ai customers to (a) audit OAuth-connected applications in each SaaS tenant for the Context.ai app and revoke if unused, (b) review 30 days of API activity for the Context.ai application against the published IOC ranges, and (c) rotate any credentials, certificates, or tokens that may have been stored in connected Google Drive, SharePoint, or Notion workspaces.
The incident is representative of a growing class of SaaS integration-layer supply chain attacks (analogues: Okta support breach 2023, Snowflake credential abuse 2024, Midnight Blizzard / Microsoft OAuth 2024). It does not correspond to a software CVE — there is no vulnerable version to patch — and detection relies entirely on SaaS audit-log anomaly analytics, OAuth app inventory hygiene, and rigorous data-access scope review.
MITRE ATT&CK techniques used in TL-2026-0398
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship
Discovery
T1087.004 Account Discovery: Cloud Account; T1526 Cloud Service Discovery
Collection
T1114.002 Email Collection: Remote Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.005 Cloud Instance Metadata API
Exfiltration
T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Lateral Movement
T1550 Use Alternate Authentication Material
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Resource Development
T1583 Acquire Infrastructure; T1583.008 Malvertising
credential-access
Affected products and versions in Context.ai OAuth Token Compromise
- Context.ai — Context.ai SaaS data-ingestion platform
Vulnerable versions: All tenants with connected OAuth integrations as of 2026-04-19
Fixed in: Post-incident token rotation completed 2026-04-19T22:00Z; all customers required to re-authorize - Salesforce — Salesforce Connected Apps (Context.ai integration)
Vulnerable versions: Any Salesforce org that granted Context.ai OAuth scopes before 2026-04-19
Fixed in: Mitigated by revoking the Context.ai Connected App in Setup > Connected Apps OAuth Usage - Google — Google Workspace (Context.ai third-party app)
Vulnerable versions: Any Workspace domain that authorized Context.ai with drive.readonly scope before 2026-04-19
Fixed in: Mitigated via Admin Console > Security > API Controls > App Access Control — block Context.ai - Slack — Slack (Context.ai app integration)
Vulnerable versions: Any workspace that installed the Context.ai app before 2026-04-19
Fixed in: Mitigated via Workspace Admin > Apps > remove Context.ai - HubSpot — HubSpot Connected Apps (Context.ai)
Vulnerable versions: Any HubSpot portal that connected Context.ai before 2026-04-19
Fixed in: Revoke via Settings > Integrations > Connected Apps - Microsoft — Microsoft 365 Enterprise Apps (Context.ai)
Vulnerable versions: Any tenant that granted the Context.ai Enterprise App admin consent before 2026-04-19
Fixed in: Revoke via Entra ID > Enterprise Applications > Context.ai > Remove - Notion Labs — Notion (Context.ai integration)
Vulnerable versions: Any workspace with the Context.ai integration installed before 2026-04-19
Fixed in: Revoke via Settings & Members > Connections - Zendesk — Zendesk (Context.ai app)
Vulnerable versions: Any Zendesk instance with the Context.ai app installed before 2026-04-19
Fixed in: Remove via Zendesk Marketplace app management - GitHub — GitHub OAuth App (Context.ai)
Vulnerable versions: Any org that authorized the Context.ai OAuth App before 2026-04-19
Fixed in: Revoke via Organization Settings > Third-party access
Remediation for Context.ai OAuth Token Compromise
Immediate actions
- Revoke the Context.ai OAuth application from every SaaS tenant (Salesforce Connected Apps, Google Workspace third-party apps, Slack app directory, HubSpot Connected Apps, Microsoft 365 Enterprise Apps, Notion integrations, Zendesk apps, GitHub OAuth apps) even if you plan to reconnect — this invalidates any refresh token still held by the actor.
- Block the published Context.ai-abuse IOC IP ranges (Hetzner, OVH, DigitalOcean subnets and NSOCKS residential proxy ranges from Wiz IOC list) at SaaS tenant-level IP allowlists where supported.
- Force-rotate any credential, SAML signing cert, API key, or token that was stored in documents accessible to Context.ai via Google Drive, SharePoint, Notion, or Slack file uploads in the 30 days prior to 2026-04-19.
- Audit Salesforce, HubSpot, and Slack audit logs for 2026-04-08 through 2026-04-19 for activity attributed to the Context.ai service principal and flag any bulk data reads.
- Rotate AWS access keys and GCP service account keys for any key that was ever present in a Google Drive document and issue CloudTrail / Admin Activity alerts for their future use.
Workarounds
- If immediate revocation is operationally infeasible, restrict the Context.ai Connected App to a minimal IP allowlist covering only documented Context.ai CIDRs (context.ai/security/ip-ranges) and monitor for drift.
- Temporarily disable the Context.ai integration and rely on a manual CSV export workflow until vendor delivers a post-incident attestation.
Longer-term hardening
- Implement SaaS-to-SaaS OAuth inventory management (SSPM tooling: Adaptive Shield, AppOmni, Obsidian, Valence) to continuously track third-party apps and their scopes across every tenant.
- Enforce least-privilege OAuth scopes — prefer per-object or per-channel scopes over read:all or drive.readonly wherever the vendor supports it.
- Require mandatory IP allowlisting on OAuth-connected applications where the SaaS supports it (Salesforce IP restrictions on Connected App, Google Workspace context-aware access, Okta network zones).
- Deploy UEBA / audit log anomaly detection on SaaS tenant audit logs to catch bulk reads by integration service principals outside their historical baseline.
- Adopt short-lived OAuth tokens with DPoP or sender-constrained credentials where supported; rotate refresh tokens on a <=30 day schedule; pin tokens to a narrow IP CIDR.
Weaknesses (CWE) in Context.ai OAuth Token Compromise
CWE-798, CWE-522, CWE-287, CWE-552, CWE-1391
Timeline of Context.ai OAuth Token Compromise
- Context.ai merges a GitHub Actions workflow that mistakenly echoes a long-lived personal access token into a public build artifact log (root-cause precursor).
- Unknown actor harvests the leaked PAT from public GitHub build logs and authenticates to Context.ai's HashiCorp Vault via the workflow's service identity.
- Actor enumerates and exfiltrates ~3,400 OAuth refresh tokens covering Salesforce, HubSpot, Slack, Google Workspace, Microsoft 365, Notion, Zendesk, and GitHub customer integrations.
- First confirmed downstream tenant access: bulk Salesforce report export from a Fortune-500 fintech customer observed from Hetzner IP range via Context.ai service principal.
- Actor harvests Slack DM history and Google Drive documents matching regex for AWS keys and SAML signing certificates across at least 14 victim tenants.
- Wiz observes attacker using Drive-harvested AWS access keys to provision EC2 in victim accounts and forging SAML assertions (Golden SAML) using stolen IdP signing certs.
- Wiz Threat Research correlates anomalous Context.ai API traffic and alerts the vendor; Context.ai revokes all OAuth refresh tokens and forces re-authorization across its customer base.
- Wiz publishes incident writeup; Context.ai posts security advisory; CISA issues alert AA26-110A urging customers to audit OAuth-connected apps and rotate exposed credentials.
- As of 2026-05-29, the specific Context.ai token theft is contained — Context.ai revoked all OAuth refresh tokens on 2026-04-19 and forced re-auth — but the actor (claimed ShinyHunters, no arrests) and the OAuth-refresh-token-abuse TTP stay actively exploited, with stolen Vercel data still extorted on BreachForums and related SaaS-integration campaigns (Canvas, Drift) ongoing through May 2026.
Sources cited for Context.ai OAuth Token Compromise
- Wiz Research: Context.ai OAuth Token Compromise
- Context.ai Security Incident Disclosure
- CISA Alert AA26-110A: SaaS OAuth Token Abuse in Supply Chain Attacks
- BleepingComputer: Context.ai OAuth token breach exposes SaaS supply chain
- MITRE ATT&CK: T1528 Steal Application Access Token
- MITRE ATT&CK: T1199 Trusted Relationship
- Salesforce Admin Advisory: Revoking Context.ai Connected App
- Google Workspace Security: Blocking Context.ai Third-Party App
- Wiz IOC List (Context.ai OAuth Abuse)
- CSA OAuth 2.0 Best Current Practice (RFC 9700)
Threats related to Context.ai OAuth Token Compromise
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration
- Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub Tokens
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches
Detection coverage for TL-2026-0398
As of 2026-04-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0398 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.